Auto-Update: 2025-02-25T11:00:53.979787+00:00

This commit is contained in:
cad-safe-bot 2025-02-25 11:04:23 +00:00
parent e10426ac1b
commit 751d524444
4 changed files with 140 additions and 27 deletions

View File

@ -0,0 +1,60 @@
{
"id": "CVE-2024-13693",
"sourceIdentifier": "security@wordfence.com",
"published": "2025-02-25T10:15:09.643",
"lastModified": "2025-02-25T10:15:09.643",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@wordfence.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "security@wordfence.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"references": [
{
"url": "https://themeforest.net/item/enfold-responsive-multipurpose-theme/4519990#item-description__changelog",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/61a9ad18-28d4-488c-b3a7-e35745f9c83e?source=cve",
"source": "security@wordfence.com"
}
]
}

View File

@ -0,0 +1,60 @@
{
"id": "CVE-2024-13695",
"sourceIdentifier": "security@wordfence.com",
"published": "2025-02-25T10:15:09.940",
"lastModified": "2025-02-25T10:15:09.940",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 via the 'attachment_id' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@wordfence.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.1,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "security@wordfence.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"references": [
{
"url": "https://themeforest.net/item/enfold-responsive-multipurpose-theme/4519990#item-description__changelog",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b55722f9-a0b9-4484-bd3b-c21dbe5716ee?source=cve",
"source": "security@wordfence.com"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2025-02-25T09:00:34.170840+00:00
2025-02-25T11:00:53.979787+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2025-02-25T08:15:30.020000+00:00
2025-02-25T10:15:09.940000+00:00
```
### Last Data Feed Release
@ -33,30 +33,21 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
282253
282255
```
### CVEs added in the last Commit
Recently added CVEs: `7`
Recently added CVEs: `2`
- [CVE-2024-13494](CVE-2024/CVE-2024-134xx/CVE-2024-13494.json) (`2025-02-25T08:15:28.970`)
- [CVE-2025-1063](CVE-2025/CVE-2025-10xx/CVE-2025-1063.json) (`2025-02-25T07:15:17.127`)
- [CVE-2025-1128](CVE-2025/CVE-2025-11xx/CVE-2025-1128.json) (`2025-02-25T07:15:18.480`)
- [CVE-2025-1648](CVE-2025/CVE-2025-16xx/CVE-2025-1648.json) (`2025-02-25T07:15:18.670`)
- [CVE-2025-1673](CVE-2025/CVE-2025-16xx/CVE-2025-1673.json) (`2025-02-25T07:15:18.837`)
- [CVE-2025-1674](CVE-2025/CVE-2025-16xx/CVE-2025-1674.json) (`2025-02-25T08:15:29.887`)
- [CVE-2025-1675](CVE-2025/CVE-2025-16xx/CVE-2025-1675.json) (`2025-02-25T08:15:30.020`)
- [CVE-2024-13693](CVE-2024/CVE-2024-136xx/CVE-2024-13693.json) (`2025-02-25T10:15:09.643`)
- [CVE-2024-13695](CVE-2024/CVE-2024-136xx/CVE-2024-13695.json) (`2025-02-25T10:15:09.940`)
### CVEs modified in the last Commit
Recently modified CVEs: `4`
Recently modified CVEs: `0`
- [CVE-2024-12698](CVE-2024/CVE-2024-126xx/CVE-2024-12698.json) (`2025-02-25T08:15:28.120`)
- [CVE-2024-3727](CVE-2024/CVE-2024-37xx/CVE-2024-3727.json) (`2025-02-25T08:15:29.150`)
- [CVE-2024-50311](CVE-2024/CVE-2024-503xx/CVE-2024-50311.json) (`2025-02-25T08:15:29.530`)
- [CVE-2024-52337](CVE-2024/CVE-2024-523xx/CVE-2024-52337.json) (`2025-02-25T08:15:29.707`)
## Download and Usage

View File

@ -245982,7 +245982,7 @@ CVE-2024-12694,0,0,fd5ce307f7dc2d78ed6bb62c0f214035a73e7cf9fdec6b70316b0e708a7a2
CVE-2024-12695,0,0,847356e76f80dcd6a9629e74d6208e1016d63f8859e993b466a93556856a4538,2025-02-11T15:15:14.203000
CVE-2024-12696,0,0,70fc6f2c7a699788e28eaa4b7a2d945b659da6d876bd61c8868d6584ff12dc78,2025-01-18T07:15:08.117000
CVE-2024-12697,0,0,2459466c74ec5bec9acd976593eaf1864bd447490d29e2029863b77f5d045147,2024-12-21T07:15:09.587000
CVE-2024-12698,0,1,252fdbb06e02e30b61f71118df1ffb18c6b39343ec7f645ff342fdb7722f66cb,2025-02-25T08:15:28.120000
CVE-2024-12698,0,0,252fdbb06e02e30b61f71118df1ffb18c6b39343ec7f645ff342fdb7722f66cb,2025-02-25T08:15:28.120000
CVE-2024-12699,0,0,f1f15e132ae79e83fce4e52614f661803aa78c84f19a0d2adbe2c9bee934bb41,2025-01-07T10:15:07.143000
CVE-2024-12700,0,0,c161ba4e53ce97164ad141dae69781306c514830255596765fa43a667338faaa,2024-12-19T23:15:05.860000
CVE-2024-12701,0,0,cd6b08f28311d78389b2479a22ff0ce00f8e2d386b94e3b072290f303be9f2ff,2025-01-04T08:15:06.670000
@ -246678,7 +246678,7 @@ CVE-2024-13490,0,0,778d9fa72dbdad7c6f858cf2d129bef7c755c267cfff033efd2ee0f028125
CVE-2024-13491,0,0,37da783639fc50c7b1870d95247d096f5b860c9d9cdab94bf89aeadd8127207e,2025-02-19T12:15:31.187000
CVE-2024-13492,0,0,e986e613e4183bc9c7afb601a232e5681edf1984e4b97b5e25f6a769df2e2a60,2025-02-07T16:15:36.123000
CVE-2024-13493,0,0,4723a19a2001ff5b6cf9a55a45e451806c480b6813774962cdc7d0267b86c2ba,2025-02-14T17:15:15.230000
CVE-2024-13494,1,1,15878891f0457dc2de468d299c39f98ff850f7d8a9027d718c5c8b6980d12b3e,2025-02-25T08:15:28.970000
CVE-2024-13494,0,0,15878891f0457dc2de468d299c39f98ff850f7d8a9027d718c5c8b6980d12b3e,2025-02-25T08:15:28.970000
CVE-2024-13495,0,0,7a8bc062291cac2ab3dfb8a0fb7feeecd31abf131df44b7d6a18b1140227b207,2025-01-24T20:46:53.307000
CVE-2024-13496,0,0,192a8533534e044b339576d96e9cea7e19a2bbd248a7b183889cec35656a4f79,2025-01-24T20:45:57.463000
CVE-2024-13499,0,0,6d635dc5b8c51f2804fa43df8b3beb018f4524a3b4ba54f25865b62cf92ed7dc,2025-01-24T20:37:12.533000
@ -246837,7 +246837,9 @@ CVE-2024-13689,0,0,41b530aa4ba65a02f514116414a57fc5db58dbb6ffe52efa3c6202ae2808e
CVE-2024-1369,0,0,6f4848b431d59906fc570cd21627f350db35226c120e93c5a8a911f55c4de4fa,2024-11-21T08:50:25.857000
CVE-2024-13691,0,0,e2ffbabc297e59a5c1d2ebf52a7761c6c116f558696876672f6c292ae9c9a1ee,2025-02-21T14:22:06.687000
CVE-2024-13692,0,0,d6a2c5e09f6d6b282a84a5c98c0a0749bf62d677e316f69790d5c144cc510706,2025-02-14T06:15:20.140000
CVE-2024-13693,1,1,5cbe4ed1559c4b9d8156a0f0962eb645027900a61839ea1dd963addc4f95831a,2025-02-25T10:15:09.643000
CVE-2024-13694,0,0,f76307657ffe1cf961458e88374ab5be6334165284f8bcf86e9ac130fdc702fd,2025-02-04T18:47:41.800000
CVE-2024-13695,1,1,acc6ecbb771e054c96f9291b320a6328cb57e7b4dc275d51d86a08dcee627bf1,2025-02-25T10:15:09.940000
CVE-2024-13696,0,0,ddda7d8ee3b5db6631ae21ebb6abc15e9b483b8978d4e9a66c9fc1507010682e,2025-01-29T08:15:19.677000
CVE-2024-13698,0,0,ea43a0ffeb82eb62bdf790bb3904a4694fa6ec80884e9d936dc30a8e05897d00,2025-02-07T20:15:27.277000
CVE-2024-13699,0,0,6c179d99e1e68d225e4cf32bfc134108fb7e1de353e5a047f158d68ed9ec8ab3,2025-02-05T18:33:09.660000
@ -260914,7 +260916,7 @@ CVE-2024-37266,0,0,bfad06f4b7e0ed0e27a2ca57f40272a71ecbbd3e7c155113af0a4c4e9be37
CVE-2024-37267,0,0,2e3809ba7bc3ee639923b028bed9ab4f728ab22816fc66adeb8d662427d75a42,2024-11-21T09:23:30.370000
CVE-2024-37268,0,0,351271f712c107f29c89718f55a9f5394713e5085f67e76faabb556c7b18702f,2024-11-21T09:23:30.510000
CVE-2024-37269,0,0,50cfaed90856887542f673a1dfb88d7fd13e5fdf55b8ad491bbd60ab59cfa8f0,2024-11-01T20:24:53.730000
CVE-2024-3727,0,1,e01d59b044657bab7f9dd77eb76fad84869871fd3b92167b2bfd4de28c5193a7,2025-02-25T08:15:29.150000
CVE-2024-3727,0,0,e01d59b044657bab7f9dd77eb76fad84869871fd3b92167b2bfd4de28c5193a7,2025-02-25T08:15:29.150000
CVE-2024-37270,0,0,f4caa4cb7a36858698643ac9409e3f8a4a2754c3391a1e0c22af7a74483970db,2024-11-21T09:23:30.753000
CVE-2024-37271,0,0,65ca3130a4d1f08f82ca6f2d8768dae2cc8655fdc443d30413ce77e2735a94c3,2024-11-21T09:23:30.873000
CVE-2024-37272,0,0,a206017327195d31a4567a6d3181c370f3bb029b5e83668199b2043888bf482f,2025-01-02T12:15:18.710000
@ -270629,7 +270631,7 @@ CVE-2024-50306,0,0,36f7f15ac3ae08b343967b7d5c928ca662bb204683930d546d92959a7101f
CVE-2024-50307,0,0,effd6ec5b86bf22e86b034cf0d56aa80ef1054d58eddf4f4569fd5216a21181b,2024-10-28T13:58:09.230000
CVE-2024-5031,0,0,c2122d739677bd0d04b7d795c26d96ab35b035940f3233702cc95bfab80b9911,2025-01-31T14:18:23.003000
CVE-2024-50310,0,0,0aa8bf92cb0c2ce72d2591b8a623d6ab248b2abe4cf7e33609877fe3cb7813d1,2024-11-13T23:15:38.657000
CVE-2024-50311,0,1,b7188ed9eecc74ae8ec3e62d73a366272bbacf98c612ad23392109deaf590735,2025-02-25T08:15:29.530000
CVE-2024-50311,0,0,b7188ed9eecc74ae8ec3e62d73a366272bbacf98c612ad23392109deaf590735,2025-02-25T08:15:29.530000
CVE-2024-50312,0,0,cb8552638bbf6ba6c0c7c722a701136cfb9eb421cd36f8c4ee78283539ae1dca,2025-01-15T02:15:26.067000
CVE-2024-50313,0,0,2ebb6e8d5ed4b61328f22546f168f422473106212aad9c5d1b0ba73deadff388,2025-01-27T18:15:39.980000
CVE-2024-50315,0,0,4cc2faf3d8c489bc195ea9b1b71e3db71fb7f18259f91c4f6bf82e911f7ad06a,2024-11-06T18:15:06.173000
@ -271941,7 +271943,7 @@ CVE-2024-52332,0,0,58837c5feb4aa8da96238f281eca729502def4e6f29469edf4244234ba0fc
CVE-2024-52333,0,0,e1bc57a7d739bdd387fb07cc28b3547c00461f3445b0a694a0bfc9660ebe8df6,2025-01-13T16:15:17.990000
CVE-2024-52335,0,0,e1e5dff8245ade7d0df486779ba826bca2b65cb6a4f443a05cb574ac0185e48c,2024-12-06T14:15:21.230000
CVE-2024-52336,0,0,b6e9b11addff6749adae872dd38056b35e5782b328e6ea56a9be94620e0c21ab,2025-02-03T20:15:33.123000
CVE-2024-52337,0,1,58eeda741c60a1d4fb3fe453cfdbe1fe3d3477077068eb2b8481a732797f56d5,2025-02-25T08:15:29.707000
CVE-2024-52337,0,0,58eeda741c60a1d4fb3fe453cfdbe1fe3d3477077068eb2b8481a732797f56d5,2025-02-25T08:15:29.707000
CVE-2024-52338,0,0,9bcca0f5584def2789a1613da17d1dfa11f003cf9877e634fced8f070cd4a571,2024-11-29T15:15:17.550000
CVE-2024-52339,0,0,8c254a85b0cc7761c2c8f8cf7f1a34f104621eefc5d8f80c80f60233cb82f4fd,2024-11-19T21:57:32.967000
CVE-2024-5234,0,0,3621dd7a9355ab69fb44113adac5d6db321db5bd9e4f974601bbdcdbc1644b98,2024-11-21T09:47:14.493000
@ -279510,7 +279512,7 @@ CVE-2025-1058,0,0,f0fad2f3f49afeee020cd5166bcf442481ddfb4558eb17fc96aa811a077ae5
CVE-2025-1059,0,0,0ab1d4e680647fc777b1f82262b0090b83c24b4ef86b71d82e6bf1295dac9761,2025-02-13T06:15:21.680000
CVE-2025-1060,0,0,a3af803539184a670e8a1150c8d0a2bc56d4cd2cc859a7263777d630bbc1a271,2025-02-13T06:15:22.213000
CVE-2025-1061,0,0,719d74f0f0646df1bcdf5186f15b6b006503d4de7dcd7fdf659e983ae5a27990,2025-02-07T02:15:29.587000
CVE-2025-1063,1,1,8afe3c738078e31fad93ae55cbf7f8953e765aa6c89218563942d00ddb291339,2025-02-25T07:15:17.127000
CVE-2025-1063,0,0,8afe3c738078e31fad93ae55cbf7f8953e765aa6c89218563942d00ddb291339,2025-02-25T07:15:17.127000
CVE-2025-1064,0,0,500ef5063a1dcfd1d0d371b2736d518324e33316060bf1c6b50d05c5b5f0c0fc,2025-02-20T09:15:09.903000
CVE-2025-1065,0,0,91e01129540d7e7c24b479977792864ebaeaee2a2b34fb9700bbb79776ce5735,2025-02-19T06:15:21.507000
CVE-2025-1066,0,0,3fc22615f942b72b8cf5d09f7bd097e7cf373f3b0fcdec9d31e667deb7a70a15,2025-02-18T19:15:24.243000
@ -279548,7 +279550,7 @@ CVE-2025-1117,0,0,2322fdff6f8393d6ada2664cbf25a349bfc8c7b701fcb01c2d988bad4837c7
CVE-2025-1118,0,0,08dbece94ae19fdcd18b85fa691f3f9bb7825229c46002214642d54efce1c781,2025-02-19T18:15:24.280000
CVE-2025-1126,0,0,75a0af68b2de42873e4ee33ccd68bb162ec9dabf122dea8ebb0bf11a24b953a1,2025-02-11T17:15:23.537000
CVE-2025-1127,0,0,964bb8e082be5f4c3ffe02b7d66d3573c4a806865108fd7e7f64bea0f60eef31,2025-02-13T19:15:14.153000
CVE-2025-1128,1,1,dd3b521c9d35aaea9cdadd37335dd1c9e2a9eed9397d5af5fc2fea4fd00d1cd7,2025-02-25T07:15:18.480000
CVE-2025-1128,0,0,dd3b521c9d35aaea9cdadd37335dd1c9e2a9eed9397d5af5fc2fea4fd00d1cd7,2025-02-25T07:15:18.480000
CVE-2025-1132,0,0,3424c330466090d5297bd63dd5fe1aae7e1a6ca50282c14840e1ac3ef43c3c89,2025-02-19T09:15:10.417000
CVE-2025-1133,0,0,9f79f2995beb7832e570964f0d4fe6b70b4d4055c401db38d148651bb480025f,2025-02-19T09:15:10.550000
CVE-2025-1134,0,0,0e3e808b725a6fc9954c97d1b5ee01f95958a0e92a4cba7aa26855000bff3aeb,2025-02-19T09:15:10.687000
@ -279770,10 +279772,10 @@ CVE-2025-1643,0,0,0826f7bcb7f1228229f5784ef58304115e16bc976b45b1d92545793ce6bb0c
CVE-2025-1644,0,0,c089c614bad147aba27db7e276630bda628e1050898eb7eafd3da256285acd5e,2025-02-25T02:15:14.863000
CVE-2025-1645,0,0,f84c25d5345ae177afb924fbcfe7e77498beaa89bb1760e6fea90a27526a406a,2025-02-25T02:15:16.123000
CVE-2025-1646,0,0,2a4b7d7071aa381f58fc8538db2234d7602d0ccee28b6ac030ee252d12c55d09,2025-02-25T03:15:09.670000
CVE-2025-1648,1,1,6db06465f3608d618d59c46dfe09a4c9e804542633ca64697fa4ad7c69d44afc,2025-02-25T07:15:18.670000
CVE-2025-1673,1,1,65913cd1f473636c65413fc4e623a1696f83129720ac5b6275f0e5547e39942d,2025-02-25T07:15:18.837000
CVE-2025-1674,1,1,aea9658bbbdcb44450b6b18ac1c08e616d00c82d64dc8139e95057e3b44f7a8f,2025-02-25T08:15:29.887000
CVE-2025-1675,1,1,919ba4e5330550da1b3bdc08ee6fe479b5b6b92bc2456a105e1c616b57e9b557,2025-02-25T08:15:30.020000
CVE-2025-1648,0,0,6db06465f3608d618d59c46dfe09a4c9e804542633ca64697fa4ad7c69d44afc,2025-02-25T07:15:18.670000
CVE-2025-1673,0,0,65913cd1f473636c65413fc4e623a1696f83129720ac5b6275f0e5547e39942d,2025-02-25T07:15:18.837000
CVE-2025-1674,0,0,aea9658bbbdcb44450b6b18ac1c08e616d00c82d64dc8139e95057e3b44f7a8f,2025-02-25T08:15:29.887000
CVE-2025-1675,0,0,919ba4e5330550da1b3bdc08ee6fe479b5b6b92bc2456a105e1c616b57e9b557,2025-02-25T08:15:30.020000
CVE-2025-20014,0,0,9692e5cd581a413def58e50a6734c5a89401a76673de37fc6a41ad824a4429cc,2025-01-29T20:15:35.207000
CVE-2025-20016,0,0,6fccb84eb01c2cd66b422e82777f9738bfe5004121e1b551d0ae454724543c0e,2025-01-14T10:15:07.500000
CVE-2025-20029,0,0,9b8781ac9a16d1f4940e1c86f8d87c8f1f8e66cb5b362950b6fdcd60c25126c4,2025-02-05T18:15:29.573000

Can't render this file because it is too large.